<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to match MQTT Protocol and an AWS site in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85333#M80195</link>
    <description>If this is not for HTTP/HTTPS traffic, a custom application/site as you've created won't work.&lt;BR /&gt;Instead, create an FQDN Domain object which resolves based on forward DNS and use a simple TCP service to allow the relevant traffic.&lt;BR /&gt;</description>
    <pubDate>Thu, 14 May 2020 19:43:00 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-05-14T19:43:00Z</dc:date>
    <item>
      <title>How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85087#M80192</link>
      <description>&lt;P&gt;We're trying to allow traffic to a specific AWS site, which unfortunately resolves to several IP addresses and none of which we can control therefore they are dynamic. Initially, we tried creating a Custom Application/Site for this, but that appears to want to match on Web Service traffic. So then we added port 1883 to the "Web Services" that Application Control blade uses. It still isn't matching on our rule which is a source being internal networks, destination is Any, and Services and Applications is this custom app. I'm guessing that won't work as this really isn't "web" traffic in the sense it is not http or https but on a non-standard port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see Checkpoint has an application for MQTT Protocol, but I don't know if I want to allow that protocol for Every destination. Is there a way to do this without having to use Dynamic Domain objects in the destination? That is, I want to define an application that goes to specific URL names but the protocol (port) needs to match the MQTT Protocol.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 16:14:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85087#M80192</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2020-05-13T16:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85319#M80193</link>
      <description>Screenshots of what you did?&lt;BR /&gt;Does the URL in question contain the port?</description>
      <pubDate>Thu, 14 May 2020 18:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85319#M80193</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-14T18:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85329#M80194</link>
      <description>&lt;P&gt;Here is an example of the test we can run to determine connectivity.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test-AWS.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6085i3766F1171CB6C6EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Test-AWS.PNG" alt="Test-AWS.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here is the rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Allow-rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6083i6605BB2ED0A5DE94/image-size/large?v=v2&amp;amp;px=999" role="button" title="Allow-rule.png" alt="Allow-rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Source is our internal network. And this is what we have for this specific application defined inside of the Everybody_Allowed application group.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fleet.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6084i31E2FD1361E9CB7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fleet.PNG" alt="Fleet.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried multiple things, first of which was to add a service defined for TCP-8883 to the Web Browsing services in the Application Contol and URL Filtering advanced settings. That didn't appear to help. I couldn't find an application for MQTT over TLS but I did see one for MQTT (port 1883) with an application signature. I tried to clone that and specify a different port, but that didn't work likely because it wasn't matching the original application signature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As this is not normal HTTP/s traffic but is a separate protocol for IoT devices wrapped in a TLS connection (at least that is my understanding of how you can secure MQTT). I wasn't sure if I could define this in a custom application as I've seen other people post on defining an app that doesn't use the default Web Services. Are you suggesting I try adding the port 8889 to the end of the AWS URL in my URL list?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I'm trying to determine how to open all the IPs behind this first AWS Iot URL in the list above, but without having to use some form of dynamic name which requires a reverse lookup. I also don't want to just open the port 8883 to all destinations, which I know will work but seems like the brute method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 18:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85329#M80194</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2020-05-14T18:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85333#M80195</link>
      <description>If this is not for HTTP/HTTPS traffic, a custom application/site as you've created won't work.&lt;BR /&gt;Instead, create an FQDN Domain object which resolves based on forward DNS and use a simple TCP service to allow the relevant traffic.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 May 2020 19:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85333#M80195</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-14T19:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85334#M80196</link>
      <description>&lt;P&gt;Are there any concerns with using an FQDN Domain object as there were in the past with it consuming resources? I thought every time it gets to the rule it needs to do a DNS lookup? We're running R80.20SP on our gateways.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 19:47:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85334#M80196</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2020-05-14T19:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85335#M80197</link>
      <description>The main problem in the past was the lack of SecureXL acceleration for Domain objects.&lt;BR /&gt;This has been resolved since R80.10.&lt;BR /&gt;There will be some additional lookups from the gateways but beyond that, not aware of any specific performance issues.</description>
      <pubDate>Thu, 14 May 2020 19:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/85335#M80197</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-14T19:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to match MQTT Protocol and an AWS site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/182085#M80198</link>
      <description>&lt;P&gt;Hi Trevor_Bruss,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to assist a customer who wants to limit&amp;nbsp; particular string being published via MQTT protocol.&lt;/P&gt;&lt;P&gt;That string has the test "cloud" in it .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried the attached:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But doesnt seem to block anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if anyone knows how I could achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe via IPS or something ?&lt;/P&gt;&lt;P&gt;Let me know&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 09:31:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-match-MQTT-Protocol-and-an-AWS-site/m-p/182085#M80198</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2023-05-25T09:31:33Z</dc:date>
    </item>
  </channel>
</rss>

